Privacy policy

Privacy Policy

The person responsible for data processing is:
Linda Sophie Koller
Heimgartenstraße 4
84030 Ergolding

Email: info@brilamo.com

We are pleased about your interest in our online shop. Protecting your privacy is very important to us. Below, we provide detailed information about how we handle your data.

1. Access Data and Hosting

You can visit our websites without providing any personal information. Each time a webpage is accessed, the web server automatically stores a so-called server log file, which contains, for example, the name of the requested file, your IP address, the date and time of access, the amount of data transferred, and the requesting provider (access data), and documents the retrieval. These access data are evaluated exclusively for the purpose of ensuring the trouble-free operation of the site and improving our services. This serves to protect our overriding legitimate interests in presenting our offer correctly, in accordance with Article 6(1) sentence 1 letter f GDPR.

 Hosting

The services for hosting and displaying the website are partially provided by our service providers (Strato AG, Otto-Ostrowski-Straße 7, 10249 Berlin) as part of a data processing agreement on our behalf. Unless otherwise explained in this privacy policy, all access data and any data collected through designated forms on this website are processed on their servers. If you have any questions about our service providers and the basis of our cooperation with them, please contact us using the contact options described in this privacy policy.

2. Data Processing for Contract Fulfillment and Contacting

2.1 Data Processing for Contract Fulfillment

For the purpose of contract fulfillment (including inquiries and processing of any warranty and service disruption claims, as well as any legal update obligations) in accordance with Art. 6(1) sentence 1 letter b GDPR, we collect personal data when you voluntarily provide this information during your order. Mandatory fields are marked as such, as we need this data to process the contract, and we cannot ship the order without it. The data being collected can be seen in the respective input forms.

Further information regarding the processing of your data, particularly regarding the sharing of data with our service providers for order, payment, and shipping processing, can be found in the following sections of this privacy policy. After the complete fulfillment of the contract, your data will be restricted for further processing and deleted after the statutory tax and commercial retention periods, in accordance with Art. 6(1) sentence 1 letter c GDPR, unless you have expressly consented to further use of your data in accordance with Art. 6(1) sentence 1 letter a GDPR, or we reserve the right to a further data use that is legally permissible and that we inform you about in this statement.

2.2 Customer Account

If you have given your consent pursuant to Art. 6(1) sentence 1 letter a GDPR by choosing to open a customer account, we will use your data for the purpose of creating the customer account and storing your data for future orders on our website. You can delete your customer account at any time, either by sending a message to the contact options described in this privacy policy or via a specific function in your customer account. After deleting your customer account, your data will be deleted unless you have expressly consented to further use of your data in accordance with Art. 6(1) sentence 1 letter a GDPR, or we reserve the right to further data use that is legally permissible and that we inform you about in this statement.

2.3 Contacting Us

In the context of customer communication, we collect personal data to process your inquiries in accordance with Art. 6(1) sentence 1 letter b GDPR when you voluntarily provide this information when contacting us (e.g., via contact form or email). Mandatory fields are marked as such, as we need this data to process your inquiry. The data collected can be seen in the respective input forms. After fully processing your inquiry, your data will be deleted unless you have expressly consented to further use of your data in accordance with Art. 6(1) sentence 1 letter a GDPR, or we reserve the right to further data use that is legally permissible and that we inform you about in this statement.

3. Data Processing for Shipping Fulfillment

Data Processing for Contract Fulfillment
For contract fulfillment in accordance with Art. 6(1) sentence 1 letter b GDPR, we will pass on your data to the shipping service provider commissioned with the delivery, insofar as this is necessary for the delivery of the goods you ordered.

Data Sharing with Shipping Service Providers for Delivery Notification

If you have given us your explicit consent during or after your order, we will pass on your email address and phone number to the selected shipping service provider based on this consent, in accordance with Art. 6(1) sentence 1 letter a GDPR, so that they can contact you before delivery for the purpose of delivery notification or coordination.

You can revoke your consent at any time by sending a message to the contact options described in this privacy policy or directly to the shipping service provider at the contact address provided below. After revocation, we will delete the data you provided for this purpose, unless you have explicitly consented to further use of your data or we reserve the right to further data usage that is legally permissible and that we inform you about in this statement.

DHL Paket GmbH
Sträßchensweg 10
53113 Bonn
Germany

Logistico GmbH
Heideckstraße 183
47805 Krefeld
Germany

4. Data Processing for Payment Processing

When processing payments in our online shop, we collaborate with the following partners: technical service providers, financial institutions, and payment service providers.

4.1 Data Processing for Transaction Processing

Depending on the selected payment method, we will forward the data necessary for processing the payment transaction to our technical service providers, who act on our behalf under a data processing agreement, or to the appointed financial institutions or the selected payment service provider, insofar as this is necessary for processing the payment. This is done to fulfill the contract in accordance with Art. 6(1) sentence 1 letter b GDPR. In some cases, the payment service providers collect the data necessary for processing the payment themselves, for example, on their own website or through technical integration in the ordering process. In such cases, the privacy policy of the respective payment service provider applies.

If you have any questions about our payment processing partners and the basis of our cooperation with them, please contact us using the contact options described in this privacy policy.

4.2 Data Processing for Fraud Prevention and Optimization of Our Payment Processes

If applicable, we may provide our service providers with additional data, which they will use, along with the data necessary for processing the payment, as our data processors for the purpose of fraud prevention and optimizing our payment processes (e.g., invoicing, handling disputed payments, supporting accounting). This serves to protect our legitimate interests in ensuring protection against fraud and efficient payment management in accordance with Art. 6(1) sentence 1 letter f GDPR.

5. Advertising by E-Mail

Email Newsletter with Subscription

When you subscribe to our newsletter, we use the necessary or separately provided data to regularly send you our email newsletter based on your consent in accordance with Art. 6(1) sentence 1 letter a GDPR. You can unsubscribe from the newsletter at any time, either by sending a message to the contact options described below or through a link provided in the newsletter. After unsubscribing, we will remove your email address from the recipient list, unless you have explicitly consented to further use of your data in accordance with Art. 6(1) sentence 1 letter a GDPR, or we reserve the right to further data use that is legally permissible and that we inform you about in this statement.

6. Cookies and Other Technologies

6.1 General Information

To make your visit to our website more attractive and to enable the use of certain features, we use various technologies, including so-called cookies, on different pages. Cookies are small text files that are automatically stored on your device. Some of the cookies we use are deleted after the browser session ends, i.e., after you close your browser (so-called session cookies). Other cookies remain on your device and allow us to recognize your browser during your next visit (persistent cookies).

Protection of Privacy on End Devices
When using our online services, we use essential technologies to provide the telemedia service explicitly requested. The storage of information on your device or access to information already stored on your device does not require your consent in this case.

For non-essential functions, the storage of information on your device or access to information already stored on your device requires your consent. Please note that if consent is not given, certain parts of the website may not be fully usable. Any consent you may have given remains valid until you adjust or reset the respective settings on your device.

Subsequent Data Processing by Cookies and Other Technologies
We use technologies that are strictly necessary for using certain features of our website (e.g., shopping cart function). These technologies collect and process information such as your IP address, the time of visit, device and browser information, as well as data regarding your use of our website (e.g., information about the contents of the shopping cart). This serves, based on a balancing of interests, our overriding legitimate interests in optimizing the presentation of our offer, in accordance with Art. 6(1) sentence 1 letter f GDPR.

We also use technologies to fulfill our legal obligations (e.g., to prove your consent to the processing of your personal data) as well as for web analytics and online marketing. Further information, including the respective legal basis for the data processing, can be found in the following sections of this privacy policy.

You can find the cookie settings for your browser at the following links: Microsoft Edge™ / Safari™ / Chrome™ / Firefox™ / Opera™.

If you have consented to the use of these technologies under Art. 6(1) sentence 1 letter a GDPR, you can withdraw your consent at any time here or by sending a message to the contact options described in the privacy policy. Alternatively, you can also visit the following link: cookiebot.com. If you reject cookies, the functionality of our website may be limited.

6.2 Consent Manager Platform (CMP)

On our website, we use a consent management service ("Consent Manager Platform (CMP)") to inform you about the cookies and other technologies we use on our website, as well as to obtain, manage, and document your consent, if necessary, for the processing of your personal data through these technologies. This is required in accordance with Art. 6(1) sentence 1 letter c GDPR to fulfill our legal obligation under Art. 7(1) GDPR, which mandates us to be able to demonstrate your consent to the processing of your personal data. The Consent Manager Platform (CMP) used is provided by Usercentrics A/S, Havnegade 39, 1058 Copenhagen, Denmark, who processes your data on our behalf.

After you submit your cookie preferences on our website, the web server stores the following data: IP address, device information, browser information, selected language, the accessed webpage or its URL, the date and time of your consent declaration, and information about your consent behavior.

In addition, the following technologies are used, which contain information about your consent behavior: Cookies.

Your data will be deleted after one year unless you have explicitly consented to further use of your data in accordance with Art. 6(1) sentence 1 letter a GDPR, or we reserve the right to further data use that is legally permissible and about which we inform you in this statement.

7. Use of Cookies and Other Technologies

As long as you have given your consent pursuant to Art. 6(1) sentence 1 letter a GDPR, we use the following cookies and other third-party technologies on our website. Once the purpose is no longer relevant and the use of the respective technology ends, the data collected in this context will be deleted. You can withdraw your consent at any time with effect for the future. For more information on how to withdraw your consent, please refer to the section "Cookies and Other Technologies." Additional details, including the basis of our cooperation with individual providers, can be found with the respective technologies. If you have questions about the providers and the basis of our cooperation with them, please contact us via the contact options described in this privacy policy.

7.1 Use of Google Services

We use the following technologies provided by Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland ("Google"). The information automatically collected by Google technologies about your use of our website is generally transferred to a server of Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA, and stored there. No adequacy decision of the European Commission is in place for the USA. Our cooperation with them is based on the standard contractual clauses of the European Commission. Unless otherwise stated for the individual technologies, data processing is carried out based on an agreement between joint controllers according to Art. 26 GDPR. Further information on data processing by Google can be found in Google’s privacy policy.

Google Analytics

For website analysis, data (IP address, visit time, device and browser information, and information about your use of our website) is automatically collected and stored using Google Analytics, from which usage profiles are created using pseudonyms. Cookies may be used for this purpose. If you visit our website from the EU, your IP address is stored on a server located within the EU for geolocation, and then immediately deleted before the traffic is forwarded to further Google servers for processing. Data processing is carried out based on a data processing agreement with Google.

For the purpose of optimized marketing of our website, we have enabled the data sharing settings for "Google Products and Services." This allows Google to access the data collected and processed by Google Analytics and subsequently use it to improve Google services. The data sharing with Google within these settings is based on an additional agreement between the controllers. We have no influence on the subsequent data processing by Google.

For creating and conducting tests, we also use the Google Optimize extension of Google Analytics.

For optimized marketing of our website, we use the so-called User-ID feature. This allows us to assign a unique, permanent ID to your interaction data from one or more sessions on our online platforms and thus analyze your user behavior across devices and sessions.

For web analytics and advertising purposes, the Google Analytics extension uses the so-called DoubleClick cookie, which allows recognition of your browser when visiting other websites. Google will use this information to compile reports on website activity and to provide other services related to website use.

Google AdSense

Our website markets ad space for third-party advertisers through Google AdSense. These ads are displayed to you at various locations on our website. Through the so-called DoubleClick cookie, targeted advertising is enabled by collecting and processing data (IP address, visit time, device and browser information, and information about your use of our website) and by automatically assigning a pseudonymous user ID, which is used to identify interests based on visits to this and other websites.

Google Ads


For advertising purposes in Google search results and on third-party websites, when visiting our website, the so-called Google Remarketing Cookie is set, which automatically collects and processes data (IP address, visit time, device and browser information, and information about your use of our website) and enables interest-based advertising using a pseudonymous cookie ID and based on the pages you have visited. Further data processing only occurs if you have activated the "personalized ads" setting in your Google account. In this case, if you are logged in to Google during your visit to our website, Google will combine your data with Google Analytics data to create and define audience lists for cross-device remarketing.

For website analysis and event tracking, we use Google Ads Conversion Tracking to measure your subsequent behavior if you arrived at our website via a Google Ads advertisement. For this purpose, cookies may be used, and data (IP address, visit time, device and browser information, and information about your use of our website based on events predefined by us, such as visiting a webpage or subscribing to a newsletter) is collected to create usage profiles using pseudonyms.

Google reCAPTCHA
To protect our web forms from abuse and spam by automated software (so-called bots), Google reCAPTCHA collects data (IP address, visit time, browser information, and information about your use of our website) and analyzes your use of our website using JavaScript and cookies. Additionally, other cookies stored by Google services in your browser are evaluated. No personal data from the form fields will be read or stored.

Google Fonts
For uniform presentation of content on our website, data (IP address, visit time, device and browser information) is collected by the script code "Google Fonts," transmitted to Google, and processed by Google. We have no influence over this subsequent data processing.

7.2 Use of Facebook Services

Facebook Analytics

Within the Facebook Business Tools, statistics on visitor activities on our website are created using data collected via the Facebook Pixel about your use of our website. Data processing is carried out based on a data processing agreement with Facebook (by Meta). Your analysis serves the optimal presentation and marketing of our website.

Facebook Ads (Ad Manager)


Through Facebook Ads, we advertise this website on Facebook (by Meta) as well as on other platforms. We determine the parameters of the respective advertising campaign. Facebook (by Meta) is responsible for the precise execution, especially the decision on the placement of ads for individual users. Unless otherwise stated for the individual technologies, data processing is carried out based on an agreement between joint controllers pursuant to Art. 26 GDPR. The joint responsibility is limited to the collection of data and its transmission to Meta Platforms Ireland. The subsequent data processing by Meta Platforms Ireland is not covered by this agreement.

Use of the Facebook Pixel
We use the Facebook Pixel as part of the technologies provided by Meta Platforms Ireland Ltd., 4 Grand Canal Square, Dublin 2, Ireland ("Facebook (by Meta)" or “Meta Platforms Ireland”). With the Facebook Pixel, data (IP address, visit time, device and browser information, and information about your use of our website, based on predefined events such as visiting a webpage or subscribing to a newsletter) is automatically collected and stored, from which pseudonymized usage profiles are created.

As part of the so-called advanced matching, further information is collected and stored in a hashed form for matching purposes, which can identify individuals (e.g., names, email addresses, and phone numbers).

For this purpose, when you visit our website, the Facebook Pixel automatically sets a cookie that enables the recognition of your browser when visiting other websites using a pseudonymous cookie ID. Facebook (by Meta) will combine this information with other data from your Facebook account and use it to compile reports on website activities and to provide other services related to website use, particularly personalized and group-based advertising. The information automatically collected by Facebook (by Meta) technologies about your use of our website is generally transferred to a server of Meta Platforms, Inc., 1 Hacker Way, Menlo Park, California 94025, USA, and stored there. No adequacy decision of the European Commission is in place for the USA. If the data transfer to the USA falls under our responsibility, our cooperation is based on the standard contractual clauses of the European Commission. Further information on data processing by Facebook can be found in Facebook's privacy policy (by Meta).

8. Social Media

8.1 Social Plugins from Facebook (by Meta), Twitter, Instagram (by Meta), Pinterest

Our website uses social buttons from social networks. These are only embedded as HTML links on the page, so that when you visit our website, no connection to the servers of the respective provider is established. When you click on one of the buttons, the website of the respective social network opens in a new window of your browser. There, you can, for example, click the "Like" or "Share" button.

8.2 Our Online Presence on Facebook (by Meta), Instagram (by Meta), YouTube, Pinterest

If you have given your consent in accordance with Art. 6 (1) sentence 1 lit. a DSGVO to the respective social media operator, your data will be automatically collected and stored when you visit our online presence on the aforementioned social media platforms for market research and advertising purposes. Usage profiles will be created using pseudonyms. These profiles may be used to display ads, both within and outside the platforms, that are presumed to match your interests. Typically, cookies are used for this purpose. For detailed information on how the data is processed and used by the respective social media operator, as well as contact options and your rights regarding privacy protection, please refer to the privacy policies of the providers linked below. If you need any assistance regarding this, please feel free to contact us.

Facebook (by Meta)  

It is an offering of Meta Platforms Ireland Ltd., 4 Grand Canal Square, Dublin 2, Ireland ("Meta Platforms Ireland"). The information automatically collected by Meta Platforms Ireland about your use of our online presence on Facebook (by Meta) is generally transmitted to a server of Meta Platforms, Inc., 1 Hacker Way, Menlo Park, California 94025, USA, and stored there. No adequacy decision by the European Commission exists for the USA. Our cooperation with them is based on the standard contractual clauses of the European Commission. Data processing in connection with visiting a Facebook (by Meta) fan page is carried out based on an agreement between joint controllers in accordance with Art. 26 DSGVO. For more information (information on Insights data), please refer to here.

Instagram (by Meta) This is an offer from Meta Platforms Ireland Ltd., 4 Grand Canal Square, Dublin 2, Ireland ("Meta Platforms Ireland").The information automatically collected by Meta Platforms Ireland about your use of our online presence on Instagram is generally transmitted to a server of Meta Platforms, Inc., 1 Hacker Way, Menlo Park, California 94025, USA, and stored there.There is no adequacy decision from the European Commission for the USA. Our cooperation with them is based on the Standard Contractual Clauses (SCCs) of the European Commission.
The data processing in connection with the visit to an Instagram (by Meta) fanpage is carried out on the basis of an agreement between joint controllers in accordance with Art. 26 GDPR.
Further information (Information on Insights data) can be found here.

YouTube is an offering from Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland ("Google").
The information automatically collected by Google about your use of our online presence on YouTube is generally transmitted to a server of Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA, and stored there.
There is no adequacy decision from the European Commission for the USA. Our cooperation with them is based on the Standard Contractual Clauses (SCCs) of the European Commission.

Pinterest is an offering from Pinterest Europe Ltd., Palmerston House, 2nd Floor, Fenian Street, Dublin 2, Ireland ("Pinterest").The information automatically collected by Pinterest about your use of our online presence on Pinterest is generally transmitted to a server of Pinterest, Inc., 505 Brannan St., San Francisco, CA 94107, USA, and stored there.
There is no adequacy decision from the European Commission for the USA. Our cooperation with them is based on the Standard Contractual Clauses (SCCs) of the European Commission.

9. Contact Options and Your Rights

9.1 Your Rights

As a data subject, you have the following rights:

  • According to Art. 15 GDPR: The right to request information about the personal data we process about you, to the extent specified therein.
  • According to Art. 16 GDPR: The right to request the immediate correction of incorrect or the completion of your personal data stored with us.
  • According to Art. 17 GDPR: The right to request the deletion of your personal data stored with us, unless further processing is necessary for:
    • the exercise of the right to freedom of expression and information;
    • the fulfillment of a legal obligation;
    • reasons of public interest; or
    • the assertion, exercise, or defense of legal claims.
  • According to Art. 18 GDPR: The right to request the restriction of the processing of your personal data, insofar as:
    • the accuracy of the data is contested by you;
    • the processing is unlawful, but you object to the deletion;
    • we no longer need the data, but you require it for the assertion, exercise, or defense of legal claims; or
    • you have objected to the processing according to Art. 21 GDPR.
  • According to Art. 20 GDPR: The right to receive your personal data, which you have provided to us, in a structured, commonly used, and machine-readable format, or to request the transmission to another controller.
  • According to Art. 77 GDPR: The right to lodge a complaint with a supervisory authority. Typically, you can contact the supervisory authority of your usual place of residence or workplace, or our company’s headquarters.

 

Right to Object

Insofar as we process personal data as described above to protect our legitimate interests, which outweigh your interests, rights, and freedoms, you can object to this processing with effect for the future. If the processing is for direct marketing purposes, you can exercise this right at any time as described above. If the processing is for other purposes, you have the right to object only if there are reasons arising from your particular situation.

After exercising your right to object, we will no longer process your personal data for these purposes, unless we can demonstrate compelling legitimate reasons for the processing that outweigh your interests, rights, and freedoms, or if the processing is necessary for the assertion, exercise, or defense of legal claims.

This does not apply if the processing is for direct marketing purposes. In that case, we will no longer process your personal data for this purpose.

 9.2 Contact Options

If you have any questions regarding the collection, processing, or use of your personal data, or if you would like to request information, correction, restriction, or deletion of data, or if you wish to withdraw any consent given or object to a specific use of data, please contact us directly using the contact details provided in our imprint.

Privacy Policy created with the Trusted Shops Legal Text Generator.